CVE-2025-59968

A

Missing Authorization vulnerability in the Juniper Networks Junos Space Security Director allows an unauthenticated network-based attacker to read or modify metadata via the web interface.  Tampering with this metadata can result in managed SRX Series devices permitting network traffic that should otherwise be blocked by policy, effectively bypassing intended security controls. This issue affects Junos Space Security Director * all versions prior to 24.1R3 Patch V4 This issue does not affect managed cSRX Series devices.

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:juniper:space_security_director:*:*:*:*:*:*:*:*
cpe:2.3:a:juniper:space_security_director:24.1:r1:*:*:*:*:*:*
cpe:2.3:a:juniper:space_security_director:24.1:r2:*:*:*:*:*:*
cpe:2.3:a:juniper:space_security_director:24.1:r3:*:*:*:*:*:*
OR cpe:2.3:a:juniper:vsrx:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx1500:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx1600:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx2300:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx300:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx320:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx340:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx345:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx380:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4100:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4120:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4200:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4300:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4600:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4700:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx5400:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx5800:-:*:*:*:*:*:*:*

History

23 Jan 2026, 19:59

Type Values Removed Values Added
First Time Juniper srx4700
Juniper srx5400
Juniper srx5600
Juniper srx5800
Juniper
Juniper srx4100
Juniper vsrx
Juniper srx4120
Juniper srx1600
Juniper srx380
Juniper srx300
Juniper srx4600
Juniper space Security Director
Juniper srx320
Juniper srx345
Juniper srx2300
Juniper srx4200
Juniper srx4300
Juniper srx340
Juniper srx1500
CPE cpe:2.3:a:juniper:vsrx:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4120:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx340:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx2300:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx345:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4700:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx1500:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4600:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4200:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx5800:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx5400:-:*:*:*:*:*:*:*
cpe:2.3:a:juniper:space_security_director:24.1:r3:*:*:*:*:*:*
cpe:2.3:a:juniper:space_security_director:24.1:r2:*:*:*:*:*:*
cpe:2.3:h:juniper:srx320:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx380:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4300:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx300:-:*:*:*:*:*:*:*
cpe:2.3:a:juniper:space_security_director:24.1:r1:*:*:*:*:*:*
cpe:2.3:h:juniper:srx5600:-:*:*:*:*:*:*:*
cpe:2.3:a:juniper:space_security_director:*:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx1600:-:*:*:*:*:*:*:*
cpe:2.3:h:juniper:srx4100:-:*:*:*:*:*:*:*
CWE CWE-862
References () https://supportportal.juniper.net/JSA103157 - () https://supportportal.juniper.net/JSA103157 - Vendor Advisory
References () https://www.juniper.net/documentation/us/en/software/nm-apps24.1/junos-space-security-director/topics/task/junos-space-metadata-creating.html - () https://www.juniper.net/documentation/us/en/software/nm-apps24.1/junos-space-security-director/topics/task/junos-space-metadata-creating.html - Technical Description

09 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-09 16:15

Updated : 2026-01-23 19:59


NVD link : CVE-2025-59968

Mitre link : CVE-2025-59968

CVE.ORG link : CVE-2025-59968


JSON object : View

CWE
CWE-862

Missing Authorization